Network boundary protection perception system and method based on intelligent crystal head

Through the locking device and risk assessment technology of the intelligent crystal head, the problems of insufficient coverage and low operation and maintenance efficiency of the traditional network boundary protection system are solved, automated management and dynamic security protection are realized, and the security and operation and maintenance efficiency of the network boundary are improved.

CN120185919BActive Publication Date: 2025-09-23GANSU ELECTRIC POWER TIANSHUI POWER SUPPLY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510549122.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-09-23
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

Traditional network boundary protection systems are difficult to cover the entire network boundary, cannot effectively deal with lateral penetration and data leakage within the intranet, and the operation and maintenance personnel have low work efficiency when managing complex network ports.

Method used

The network boundary protection perception system adopts intelligent crystal head, which realizes automatic management and risk assessment by setting locking devices and unique identity identification codes on the crystal head, generates warning instructions to control the connection or removal of the crystal head, and records transmission logs for security event tracing.

Benefits of technology

It improves the work efficiency of operation and maintenance personnel in managing network ports, reduces the security risks caused by human operational errors, and realizes refined management and dynamic security protection of network connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185919B_ABST
    Figure CN120185919B_ABST
Patent Text Reader

Abstract

This solution belongs to the field of network security technology, and specifically relates to a network boundary protection perception system and method based on an intelligent crystal head. The network boundary protection perception method based on an intelligent crystal head includes the following steps: S10: a locking device is set on the crystal head, and a unique identity identification code is set for the locking device as a locking code, the locking device is used to receive a first instruction from the management terminal, and control the crystal head to be unplugged or connected to the network port according to the content of the first instruction; the state of the crystal head being connected to the network port or unplugged from the network port is obtained as the first state information through the locking code, and the first state information is initialized to the state of the network port being unplugged through the locking code; S20: the first state information is obtained, and when the first state information is the state of the accessed network port, the transmission data passing through the crystal head is monitored as the first data. This solution not only solves the problem of low work efficiency of operation and maintenance personnel when managing complex network ports, but also significantly improves the work quality of operation and maintenance personnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This solution belongs to the field of network security technology, and specifically relates to a network boundary protection perception system and method based on an intelligent crystal head. Background Art

[0002] With the continued expansion of networks and the acceleration of digitalization, modern network environments are characterized by diverse device types, complex access methods, and diverse communication protocols, presenting new challenges for network security. Traditional perimeter security systems primarily rely on firewalls, IDS / IPS, and other devices deployed at the core network egress. This centralized protection model has significant limitations: First, it struggles to cover the entire network perimeter, resulting in numerous security blind spots at the access layer; second, it fails to effectively address the risks of lateral penetration and data leakage within the intranet, leading to frequent and difficult-to-trace security incidents such as unauthorized plugging and unplugging and abnormal communications.

[0003] In this regard, Chinese patent CN112714107A discloses a terminal single-channel intelligent network port lock and its system and control method. By combining the shell design of the RJ45 terminal and a micro-stepping motor, a lock body structure is formed on the RJ45 terminal. Once inserted into the network port, it cannot be manually unlocked and unplugged. The operator's identity and authority authentication is required. Only authorized operators can use the built-in micro-stepping motor to drive the locking spring sheet to press down, unlock the RJ45 terminal, and unplug it. This effectively prevents other people from accidentally unplugging confidential network cables involved in confidential calculations, and prevents others from privately connecting or replacing network cables.

[0004] However, in actual operation, if a large number of RJ45 connectors need to be unplugged simultaneously, the operator must authenticate each RJ45 connector individually and unlock the RJ45 connectors to remove them. In real-world scenarios, operators often have to manage a large number of network ports (and RJ45 connectors). This requirement of verifying each RJ45 connector individually increases operator time and reduces efficiency. Summary of the Invention

[0005] The purpose of this solution is to provide a network boundary protection perception system and method based on intelligent crystal head to solve the problem of low work efficiency of operation and maintenance personnel when managing complex network ports.

[0006] To achieve the above objectives, this solution provides a network boundary protection perception method based on intelligent crystal head, including the following steps:

[0007] S10: A locking device is provided on the RJ45 connector, and a unique identification code is provided for the locking device as a locking code. The locking device is configured to receive a first instruction from the management terminal and control the RJ45 connector to be connected to or unplugged from the network port according to the content of the first instruction. The state of the RJ45 connector being connected to or unplugged from the network port is obtained as first state information based on the locking code, and the first state information is initialized to a state of the network port being unplugged based on the locking code.

[0008] S20: Obtaining first status information. When the first status information indicates a network port access status, monitoring data transmitted through the RJ45 connector as first data, obtaining information of communication terminals at both ends of the RJ45 connector that transmit the first data as first terminals, and storing the first terminal, locking code, first data, and monitoring time of the first data as a transmission log; and performing a risk assessment on the locking device corresponding to the locking code based on the data type of the first data and the first terminal in the transmission log.

[0009] S30: Obtaining a transmission log, performing a data flow statistical analysis on the transmission log, and performing a risk assessment on the locking device corresponding to the locking code based on the statistical analysis results;

[0010] S40: Generate a warning instruction based on the risk assessment result, and send the warning instruction to the locking device corresponding to the locking code. The locking device receives the warning instruction and controls the crystal head to connect or unplug the network port according to the warning instruction; send the transmission log corresponding to the warning instruction as a risk log to the management terminal.

[0011] And, a network boundary protection perception system based on an intelligent crystal head using a network boundary protection perception method based on an intelligent crystal head.

[0012] The principles and technical benefits of this solution are as follows: First, through the use of a locking device and its unique identification code (locking code), this solution effectively prevents unauthorized access to and removal of network cables. Before receiving instructions from the management terminal, the locking device initializes the RJ45 connector to the unplugged network port state, thus preventing unauthorized access in this initial state. This approach eliminates the clutter of manual record keeping (for multiple network ports) and effectively prevents unauthorized RJ45 connector access. This precise, automated approach improves the efficiency of operations and maintenance personnel managing a large number of network ports.

[0013] Secondly, the locking device in this solution automatically receives commands from the management terminal and executes them, eliminating the need for operators to individually verify identity permissions or manually manage network ports. When a risk is detected, an alert is automatically generated and the locking device is activated, eliminating the need for manual intervention. This automated approach not only saves operator time and effort, but also reduces safety risks caused by human error, further improving the efficiency and quality of their work.

[0014] Furthermore, this solution provides strong support for network management and security incident tracing by recording transmission and risk logs. Detailed information about each network connection (including the communication terminal, transmitted data, monitoring time, and lock code) is stored as a transmission log. When a risk is detected, the corresponding transmission log is sent to the management terminal as a risk log. These logs allow administrators to easily review network connection history and detailed security event information, enabling refined management of network access devices. This traceability and refined management capabilities further improve the efficiency and quality of operations and maintenance personnel managing a large number of network ports.

[0015] In summary, this solution not only solves the problem of low work efficiency of operation and maintenance personnel when managing a large number of network ports, but also significantly improves the work quality of operation and maintenance personnel.

[0016] Furthermore, the locking device includes a body and a shell, the body being slidably connected to the shell inside the shell, and one end of the body being provided with an elastic pin; a first limiting groove is provided on one side of the shell, and when the body slides from one end of the shell to the other end, the pin of the body slides into the first limiting groove and slides from the inside of the shell to the outside of the shell; a spring is fixedly connected to the outside of the shell, one end of the spring is fixedly connected to the shell, and the spring and the shell form a certain angle, and a first electromagnet is embedded in the shell on one side of the angle, and a second limiting groove is provided on one side of the first electromagnet, and a second electromagnet is slidably connected in the second limiting groove, and one end of the second electromagnet is fixedly connected to the body; when the first electromagnet attracts the second electromagnet, the pin slides into the first limiting groove, and the second electromagnet slides to one end of the second limiting groove, and the second electromagnet blocks the spring from pressing down under the spring; when the first electromagnet repels the second electromagnet, the pin slides to the inside of the shell, and the second electromagnet slides to the other end of the second limiting groove, and the second electromagnet no longer blocks the spring from pressing down.

[0017] Through the interaction between the first and second electromagnets, the locking device reliably locks and unlocks the RJ45 connector. When the first electromagnet attracts the second electromagnet, the pin slides into the first retaining slot, and the spring is blocked by the second electromagnet, preventing it from pressing downward. This locks the connector and prevents it from being removed. When the first electromagnet repels the second electromagnet, the pin slides back into the housing, freeing the spring and allowing it to press downward. This unlocks the connector and allows it to be removed. This design ensures that the RJ45 connector can only be removed or inserted under specific electromagnetic control signals, effectively preventing unauthorized insertion and removal. This approach also enables remote control and automated management. The management terminal can control the state of the first electromagnet by sending specific electrical signals, thereby locking or unlocking the RJ45 connector. This not only improves management efficiency but also reduces the need for on-site operations by maintenance personnel, further enhancing the automation of network management. Furthermore, the electromagnetic signal or relative position between the first and second electromagnets can be used to determine whether the RJ45 connector is connected to the network port, saving maintenance personnel time and further improving their work efficiency.

[0018] Furthermore, when the crystal head is connected to the network port, the position information of the crystal head is obtained as the first position according to the communication address of the network port, the position information of the management terminal is obtained as the second position, the locking code in the risk log received by the management terminal is obtained as the first code, the first position of the locking device corresponding to the first code is obtained, and a pull-out application is generated according to the distance between the first position and the second position and sent to the management terminal, and feedback information of the pull-out application is received, and the feedback information of the pull-out application is rejection or approval; when the feedback information of the pull-out application received is approval, the locking device controls the first electromagnet to repel the second electromagnet.

[0019] A disconnect request is generated based on the location of the RJ45 connector and the management terminal. The disconnect operation is executed after the operator agrees to the disconnect. This method significantly reduces the time it takes for operators to locate a faulty RJ45 connector. In scenarios where multiple network ports are concentrated, this effectively reduces the time it takes for operators to locate the target RJ45 connector, improving their work efficiency. Furthermore, by obtaining the relative location and sending the disconnect request to the operator, the operator can reduce the time it takes to locate nearby network ports, further improving work efficiency. This method also prevents operators from disconnecting the wrong network port due to misplaced connections, thereby improving work quality.

[0020] Furthermore, when performing a risk assessment on the locking device corresponding to the locking code according to the data type of the first data in the transmission log and the first terminal, the data type of the first data is first identified, the data type includes structured data, semi-structured data and unstructured data, and the first data is classified according to the identification result; then, according to the data type and the corresponding risk feature, the risk feature in the first data is identified and extracted as the first feature, and then, according to each data type of the first data, the risk assessment index is calculated according to the first feature, and the risk assessment index includes the structured data risk assessment index. , semi-structured data risk assessment indicators , Unstructured Data Risk Assessment Indicators ; Then calculate the comprehensive risk value based on the risk assessment indicators of the data type , The calculation formula is as follows:

[0021] (1),

[0022] in, Indicates the The proportion of the data type in the first data; then according to the comprehensive risk value Risk levels are divided and stored in association with lock codes.

[0023] This solution can more accurately identify potential risks in the data transmission process by dividing data into three types: structured, semi-structured, and unstructured, and extracting different risk characteristics for each type. The calculation formula of the comprehensive risk value takes into account the proportion of different types of data in the transmitted data, which means that the evaluation results can dynamically reflect the actual risk of the current data transmission, so that this solution can adjust the status of the locking device in time according to the risk level, such as restricting access or unplugging the network port, thereby achieving dynamic risk management and real-time response. This solution associates the risk level with the locking code for storage, which can track and manage the risk status of each locking device, which is convenient for subsequent security audits and problem tracing, and can also achieve personalized management of each locking device, adopt different security strategies according to its risk level, and can also quickly query and manage the risk status of the locking device through the locking code, without the need to evaluate each device separately, thereby improving management efficiency.

[0024] Furthermore, when performing data flow statistics analysis on the transmission log, the transmission log is segmented into fixed time windows or dynamic windows based on flow fluctuations, and the sliding window mean The calculation formula is shown in the following formula (2):

[0025] (2),

[0026] in, For the front The flow value of the time window; and according to the sliding window mean To detect sudden increase in traffic, the sudden increase rate of traffic is calculated as shown in the following formula (3):

[0027] (3),

[0028] If the burst rate exceeds the preset burst threshold, the corresponding data in the transmission log will be marked as a risk log; the total amount of data transmitted in the first data transmission in each time window is counted, the average traffic per unit time is calculated, the traffic proportion of different protocols is counted, the degree of deviation between the traffic peak and the mean is detected, and the connection frequency and session duration from the sending source to the receiving destination terminal are analyzed; and the entropy value of the protocol distribution in the transmission log is calculated to evaluate the traffic concentration. , The calculation formula is shown in the following formula (4):

[0029] (4),

[0030] in, For the The traffic proportion of the protocol; the number of connections of the same first terminal in the transmission log is counted according to the preset working time, and the connection frequency is calculated based on the number of connections; the comprehensive risk value is calculated based on the connection frequency, sudden increase rate and traffic concentration,

[0031] (5),

[0032] in, is the preset weight value.

[0033] This solution segments transmission logs into fixed time windows or dynamic windows based on traffic fluctuations and calculates the sliding window average to accurately monitor data traffic changes and promptly detect abnormal fluctuations, such as traffic spikes. If the spike rate exceeds a preset threshold, the relevant data is marked as a risk log, allowing for rapid identification of potential security threats, such as DDoS attacks. Furthermore, the solution calculates the total amount of data transmitted within each time window, calculates the average traffic volume per unit time, calculates the traffic share of different protocols, detects the deviation between traffic peaks and the average, and analyzes the connection frequency and session duration from the source to the destination terminal. These measures comprehensively analyze data traffic characteristics and provide a deep understanding of network traffic behavior, enabling more effective identification of abnormal traffic. Furthermore, by calculating the entropy of the protocol distribution in the transmission log to assess traffic concentration, it can identify anomalies in traffic distribution, such as an unusual increase in traffic for certain protocols. Furthermore, by counting the number of connections from the same primary terminal in the transmission log based on preset working hours and calculating the connection frequency, it helps detect potential abnormal behavior, such as malware command-and-control (C&C) communication. Ultimately, by combining connection frequency, burst rate, and traffic concentration to calculate a comprehensive risk value, we can comprehensively consider multiple risk factors and more comprehensively assess the security risks at the network perimeter, thereby prioritizing high-risk threats and improving security management efficiency. This approach not only enables dynamic monitoring and analysis of network traffic, adapting to real-time changes in network traffic, but also effectively improves the security protection capabilities of the network perimeter, reduces the occurrence of security incidents, and ensures the safe and stable operation of the network environment.

[0034] Furthermore, when generating a warning instruction based on the risk assessment result, if the comprehensive risk value reaches a preset high risk level, a first type of instruction is generated. The locking device controls the RJ45 connector to automatically unplug the network port according to the first type of instruction and prohibits further access until the RJ45 connector automatically connects to the network port after receiving an unlock instruction sent by the management terminal. If the comprehensive risk value reaches a preset medium risk level, a second type of instruction is generated. The locking device limits the data transmission rate of the RJ45 connector according to the second type of instruction and sends a risk confirmation request to the management terminal. If the risk confirmation request does not receive a risk confirmation message from the management terminal within a preset time, the second type of instruction is upgraded to a first type of instruction. If a risk confirmation message is received from the management terminal, the RJ45 connector is controlled to unplug the network port or clear the comprehensive risk value based on the content of the risk confirmation message. If the comprehensive risk value is a preset low risk level, a third type of instruction is generated. The locking device maintains the RJ45 connector connected and opens a temporary monitoring window according to a preset monitoring time to monitor the first data. If the comprehensive risk value of the first data does not increase within the temporary monitoring time, a low risk indicator is marked in the transmission log. If the comprehensive risk value of the first data increases, the third type of instruction is upgraded to a second type of instruction.

[0035] Furthermore, when the locking device controls the removal or connection of the crystal head to the network port according to the warning instruction, if the first type of instruction is received, the first electromagnet is energized to generate a repulsive force, driving the second electromagnet to slide toward the far end of the second limit slot, and the body slides to the end away from the shell and the spring clip, so that the crystal head is pulled out of the network port; when the unlocking instruction is received, the first electromagnet is energized to generate an adsorption force, driving the body to slide back to the end close to the shell and the spring clip, completing the network port access.

[0036] This method of generating warning instructions based on risk assessment results enables refined management and dynamic adjustment of network perimeter security risks, significantly enhancing security protection capabilities. By categorizing risk levels into high, medium, and low, and generating different types of instructions for each level, this solution can implement differentiated response measures for data transmission at different risk levels. For example, high-risk data automatically removes the RJ45 connector and prohibits further access until authorized by the management terminal, effectively preventing the spread of malicious data. Medium-risk data limits the transmission rate and sends a risk confirmation request. If manual confirmation feedback is not received in a timely manner, the instruction is automatically upgraded to reduce the scope of potential threats. Low-risk data remains connected and a temporary monitoring window is opened to further confirm security and avoid misjudgments that interfere with normal business operations. This approach not only improves the flexibility and adaptability of security protection, but also reduces manual intervention, improves management efficiency, ensures the security and stability of the network perimeter, and effectively reduces the occurrence of security incidents.

[0037] Furthermore, a temperature detection device for obtaining the temperature of the crystal head body is embedded in the shell, and the temperature data obtained by the temperature detection device is used as the actual temperature data; when storing the transmission log, the transmission log is associated with the actual temperature data obtained at the same time and stored, the data transmission time in the transmission log is statistically analyzed, and the current temperature of the crystal head is estimated as the predicted temperature data based on the statistical analysis result of the data transmission time, and the predicted temperature data is compared with the actual temperature data. When the actual difference obtained by comparison exceeds the preset difference threshold, the first electromagnet is controlled to repel the second electromagnet, and the actual temperature data is obtained again. When the actual temperature data drops to the preset non-working temperature, the first electromagnet is controlled to attract the second electromagnet, and the transmission log and actual temperature data are obtained again. The predicted temperature data of the crystal head is obtained according to the data transmission time in the transmission log, and the predicted temperature data is compared with the actual temperature data; if within the preset inspection time, the number of times the first electromagnet repels the second electromagnet exceeds the preset inspection number, the first electromagnet is controlled to repel the second electromagnet, and an abnormal connection information is generated according to the locking code and sent to the management terminal.

[0038] When an RJ45 connector is connected to a network port, it generates heat due to data transmission, and the longer the transmission time, the more heat it generates. Data transmitted through the RJ45 connector is recorded in the transmission log. If the transmission log does not record any data transmission information, but the RJ45 connector is severely overheated, this indicates a connection problem with the RJ45 connector or other unrecorded data transmission issues. Disconnecting the RJ45 connector and reconnecting it after the temperature drops can partially resolve the connection issue. If the connection problem or unrecorded data transmission issue persists and is not resolved after multiple reconnection attempts, an abnormal connection information will be sent to operations and maintenance personnel for manual investigation and repair. This method can prevent the RJ45 connector from malfunctioning when a connection problem occurs, thereby preventing damage to the RJ45 connector or reducing data transmission failures. It also reduces the risk of data theft without being recorded in the transmission log, thereby protecting data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 This is a flow chart of a network boundary protection perception method based on an intelligent crystal head in an embodiment of the present invention.

[0040] Figure 2 It is a side sectional view related to the locking device in an embodiment of the present invention.

[0041] The following is a further detailed description through specific implementation methods:

[0042] The reference numerals in the drawings of the specification include: 1. buckle; 2. spring; 3. second electromagnet; 4. first electromagnet; 5. housing; 6. second limiting groove; 7. first limiting groove. DETAILED DESCRIPTION

[0043] The following will clearly and completely describe the concept and technical effects of the present invention in conjunction with the embodiments to fully understand the purpose, features and effects of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, other embodiments obtained by those skilled in the art without creative work are all within the scope of protection of the present invention:

[0044] like Figure 1 As shown, the network boundary protection perception method based on the intelligent crystal head includes the following steps:

[0045] S10: A locking device is provided on the RJ45 connector, and a unique identification code is provided for the locking device as a locking code. The locking device is configured to receive a first instruction from the management terminal and control the RJ45 connector to be connected to or unplugged from the network port according to the content of the first instruction. The state of the RJ45 connector being connected to or unplugged from the network port is obtained as first state information based on the locking code, and the first state information is initialized to a state of the network port being unplugged based on the locking code.

[0046] S20: Obtaining first status information. When the first status information indicates a network port access status, monitoring data transmitted through the RJ45 connector as first data, obtaining information of communication terminals at both ends of the RJ45 connector that transmit the first data as first terminals, and storing the first terminal, locking code, first data, and monitoring time of the first data as a transmission log; and performing a risk assessment on the locking device corresponding to the locking code based on the data type of the first data and the first terminal in the transmission log.

[0047] S30: Obtaining a transmission log, performing a data flow statistical analysis on the transmission log, and performing a risk assessment on the locking device corresponding to the locking code based on the statistical analysis results;

[0048] S40: Generate a warning instruction based on the risk assessment result, and send the warning instruction to the locking device corresponding to the locking code. The locking device receives the warning instruction and controls the crystal head to connect or unplug the network port according to the warning instruction; send the transmission log corresponding to the warning instruction as a risk log to the management terminal.

[0049] Among them, such as Figure 2 As shown, the locking device includes a body and a shell 5, the body is slidably connected to the shell 5 inside the shell 5, and an elastic pin is provided at one end of the body; a first limiting groove 7 is provided on one side of the shell 5, and when the body slides from one end of the shell 5 to the other end, the pin of the body slides into the first limiting groove 7 and slides from the inside of the shell 5 to the outside of the shell 5; a spring piece 2 is fixedly connected to the outside of the shell 5, one end of the spring piece 2 is fixedly connected to the shell 5, and the spring piece 2 forms a certain angle with the shell 5, and a buckle 1 is provided on the outside of the angle on the spring piece 2, and a first electromagnet 4 is embedded in the shell 5 on one side of the angle, and a second limiting groove 6 is provided on one side of the first electromagnet 4, and a second electromagnet 3 is slidably connected in the second limiting groove 6, and one end of the second electromagnet 3 is fixedly connected to the body.

[0050] When the first electromagnet 4 attracts the second electromagnet 3, the pin slides into the first limiting groove 7, and the second electromagnet 3 slides to one end of the second limiting groove 6, and the second electromagnet 3 blocks the spring piece 2 from pressing down below; when the first electromagnet 4 repels the second electromagnet 3, the pin slides into the inside of the housing 5, and the second electromagnet 3 slides to the other end of the second limiting groove 6, and the second electromagnet 3 no longer blocks the spring piece 2 from pressing down.

[0051] When the shell 5 is inserted into the network port, the angle between the spring piece 2 and the shell 5 decreases under the restriction of the network port, the buckle 1 enters the network port, and the spring piece 2 accumulates elastic potential energy. At this time, if the first electromagnet 4 attracts the second electromagnet 3 (the crystal plug is connected to the network port), the second electromagnet 3 prevents the spring piece 2 from pressing down below the spring piece 2, and the angle between the spring piece 2 and the shell 5 cannot be reduced. Under the prevention of the buckle 1, the crystal plug cannot be pulled out of the network port by external force; if the first electromagnet 4 repels the second electromagnet 3 (the crystal plug is pulled out of the network port), the second electromagnet 3 does not prevent the spring piece 2 from pressing down, and the angle between the spring piece 2 and the shell 5 can be reduced under the action of external force. After the angle between the spring piece 2 and the shell 5 is reduced, the crystal plug buckle 1 no longer prevents the crystal plug from being pulled out.

[0052] Among them, when the crystal head is connected to the network port, the location information of the crystal head is obtained as the first position according to the communication address of the network port, the location information of the management terminal is obtained as the second position, the locking code in the risk log received by the management terminal is obtained as the first code, the first position of the locking device corresponding to the first code is obtained, and a pull-out application is generated according to the distance between the first position and the second position and sent to the management terminal, and feedback information of the pull-out application is received, and the feedback information of the pull-out application is rejection or approval; when the feedback information of the received pull-out application is approval, the locking device controls the first electromagnet 4 to repel the second electromagnet 3.

[0053] Among them, when performing risk assessment on the locking device corresponding to the locking code according to the data type of the first data in the transmission log and the first terminal, the data type of the first data is first identified, and the data type includes structured data, semi-structured data and unstructured data, and the first data is classified according to the identification result; then, according to the data type and the corresponding risk feature, the risk feature in the first data is identified and extracted as the first feature, and then, according to each data type of the first data, the risk assessment index is calculated according to the first feature, and the risk assessment index includes the structured data risk assessment index , semi-structured data risk assessment indicators , Unstructured Data Risk Assessment Indicators ; Then calculate the comprehensive risk value based on the risk assessment indicators of the data type , The calculation formula is as follows:

[0054] (1),

[0055] in, Indicates the The proportion of the data type in the first data;

[0056] Based on the comprehensive risk value Risk levels are divided and stored in association with lock codes.

[0057] Specifically, The calculation formula is shown in the following formula (10): The calculation formula is shown in the following formula (11): The calculation formula is shown in the following formula (12):

[0058] (10),

[0059] (11),

[0060] (12),

[0061] in, Indicates the The data type The weight of each feature is assigned according to actual needs and meets .

[0062] When performing data flow statistics analysis on transmission logs, the transmission logs are segmented into fixed time windows or dynamic windows based on flow fluctuations, and the sliding window mean is used to calculate the average value of the transmission logs. The calculation formula is shown in the following formula (2):

[0063] (2),

[0064] in, For the front The flow value of a time window;

[0065] And according to the sliding window mean To detect sudden increase in traffic, the sudden increase rate of traffic is calculated as shown in the following formula (3):

[0066] (3),

[0067] If the burst rate exceeds the preset burst threshold, the corresponding data in the transmission log will be marked as a risk log;

[0068] Count the total amount of data transmitted in the first data transmission in each time window, calculate the average traffic per unit time, count the traffic proportion of different protocols, detect the deviation between the traffic peak and the mean, analyze the connection frequency and session duration from the sending source to the receiving destination terminal; and calculate the entropy value of the protocol distribution in the transmission log to evaluate the traffic concentration. , The calculation formula is shown in the following formula (4):

[0069] (4),

[0070] in, For the Traffic proportion of each protocol;

[0071] Counting the number of connections of the same first terminal in the transmission log according to the preset working time, and calculating the connection frequency based on the number of connections;

[0072] Calculate the comprehensive risk value based on connection frequency, sudden increase rate and traffic concentration.

[0073] (5),

[0074] in, is the preset weight value.

[0075] Among them, when a warning instruction is generated according to the risk assessment results, if the comprehensive risk value reaches a preset high risk level, a first type of instruction is generated. The locking device controls the crystal head to automatically unplug the network port according to the first type of instruction and prohibits re-access until the unlocking instruction sent by the management terminal is received, and the crystal head automatically connects to the network port.

[0076] If the comprehensive risk value reaches the preset medium risk level, a second-type instruction is generated. The locking device limits the data transmission rate of the crystal plug according to the second-type instruction and sends a risk confirmation request to the management terminal. If the risk confirmation request does not receive a risk confirmation message from the management terminal within a preset time, the second-type instruction is upgraded to a first-type instruction. If a risk confirmation message is received from the management terminal, the crystal plug is controlled to be unplugged from the network port or the comprehensive risk value is cleared according to the content of the risk confirmation message.

[0077] If the comprehensive risk value is a preset low risk level, a third type of instruction is generated, the locking device maintains the crystal head access state, opens a temporary monitoring window according to the preset monitoring time to monitor the first data, and if the comprehensive risk value of the first data does not increase within the temporary monitoring time, a low risk mark is marked in the transmission log; if the comprehensive risk value of the first data increases, the third type of instruction is upgraded to a second type of instruction.

[0078] Specifically, when the locking device controls the crystal head to be pulled out or connected to the network port according to the warning instruction, if the first type of instruction is received, the first electromagnet 4 is energized to generate a repulsive force, driving the second electromagnet 3 to slide toward the far end of the second limit groove 6, and the body slides to the end away from the shell 5 and the spring clip 2, so that the crystal head is pulled out of the network port; when the unlocking instruction is received, the first electromagnet 4 is energized to generate an adsorption force, driving the body to slide back to the end close to the shell 5 and the spring clip 2, completing the network port access.

[0079] The housing further includes a temperature detection device embedded therein for obtaining the temperature of the RJ45 connector body. The temperature data obtained by the temperature detection device is used as the actual temperature data. When storing a transmission log, the transmission log is associated with the actual temperature data obtained at the same time. The data transmission time in the transmission log is statistically analyzed. Based on the statistical analysis results of the data transmission time, the current temperature of the RJ45 connector is estimated as predicted temperature data. The predicted temperature data is compared with the actual temperature data. When the actual difference between the comparisons exceeds a preset difference threshold, the first electromagnet is controlled to repel the second electromagnet and the actual temperature data is obtained again. When the actual temperature data drops to a preset non-operating temperature, the first electromagnet is controlled to attract the second electromagnet, the transmission log and actual temperature data are obtained again, and the predicted temperature data of the RJ45 connector is obtained based on the data transmission time in the transmission log. The predicted temperature data is compared with the actual temperature data. If, within a preset inspection time, the number of times the first electromagnet repels the second electromagnet exceeds a preset number of inspections, the first electromagnet is controlled to repel the second electromagnet, and an abnormal connection message is generated based on the lock code and sent to the management terminal.

[0080] During implementation, a company used a network perimeter protection and awareness system based on intelligent RJ45 connectors. Operations and maintenance personnel used management terminals to maintain the intelligent RJ45 connectors. Employee computers used intelligent RJ45 connectors to access network ports.

[0081] One day, suppose employee A's computer is connected to the network via a smart RJ45 connector (the first status information indicates the access port). The system then begins monitoring transmitted data (first data). For example, employee A is transmitting structured data (an employee attendance report). The system obtains the communication terminal information (first terminal, i.e., employee A's computer device information) and records the first terminal, lock code, attendance report data, and monitoring time as a transmission log.

[0082] When conducting a risk assessment on the transmission log, the data type is first identified as structured data. Following the risk assessment process, risk characteristics corresponding to this structured data (such as those related to confidentiality and integrity) are extracted, and a structured data risk assessment index is calculated. Simultaneously, data flow statistics are analyzed on the transmission log, segmented into fixed time windows (e.g., 15-minute windows), and the sliding window average is calculated to monitor traffic flow. In this scenario, traffic flow is stable, with no sudden increases. The traffic proportions of different protocols are normal, and the connection frequency is consistent with daily office work patterns. Finally, combining the data type and the risk values ​​determined by the traffic statistics analysis, the system calculates a low overall risk level. Consequently, the system generates a third-type instruction, locking the device to maintain the RJ45 connection and opening a temporary listening window for a preset listening period (e.g., 30 minutes) to monitor the first data transmitted subsequently. If the overall risk value does not increase during these 30 minutes, a low risk indicator is assigned to the transmission log.

[0083] During the company's peak business period, employee B's computer (the first terminal) connected to the network via a smart RJ45 connector and transmitted a large amount of data (first data, consisting of multiple data types). After the system recorded the transmission log normally, statistical analysis of the data traffic revealed a sudden increase in traffic, with the sliding window mean calculated based on dynamic window segments exceeding the preset surge threshold. At this point, the corresponding data in the transmission log was marked as a risk log. Simultaneously, a data type-based risk assessment identified the first data as containing high-risk unstructured data (such as unencrypted R&D design documents). A comprehensive assessment of both data traffic and data types resulted in a calculated overall risk value of medium risk.

[0084] The system generates a second-type instruction. Upon receiving it, the locking device limits the data transmission rate of the RJ45 connector and sends a risk confirmation request to the management terminal. If the management terminal's operations and maintenance personnel fail to provide confirmation within the preset time, the system upgrades the second-type instruction to a first-type instruction. Upon receiving the first-type instruction, the locking device controls the first electromagnet 4 to repel the second electromagnet 3. The locking device then slides away from the end of the housing 5 where it is fixedly connected to the spring 2. The pins slide into the interior of the housing 5, disconnecting Employee B's computer from the network port.

[0085] The smart RJ45 plug in employee C's computer also loses electrical connection to the network port. Employee C presses spring 2 to remove the RJ45 plug and then re-inserts it. However, because the maintenance staff did not authorize the plug before insertion, the first electromagnet 4 repels the second electromagnet 3, and employee C's computer remains disconnected from the network port.

[0086] Employee C contacts the operation and maintenance personnel to come and connect to the Internet. The operation and maintenance personnel brings his own operation and maintenance personnel terminal (operation and maintenance personnel mobile phone) to employee C. Employee C holds his own computer and waits for the operation and maintenance personnel (the smart crystal head of employee C's computer is plugged into the network port). The system obtains employee C's location as the first location and the location of the operation and maintenance personnel's mobile phone as the second location. When the first location and the second location are less than 2 meters apart, the system sends a disconnection request to the operation and maintenance personnel's mobile phone. After checking, the operation and maintenance personnel enters "rejected" in the mobile phone as feedback information for the disconnection request. Then the first electromagnet 4 of the smart crystal head connected to employee C's computer attracts the second electromagnet 3, and employee C's computer is electrically connected to the network port.

[0087] Because the hardware of the smart crystal head connected to employee D's computer was damaged and the spring clip 2 could not be pressed, the operation and maintenance personnel authorized and turned off the smart crystal head, disconnecting the first electromagnet 4 from the power supply, and used an electromagnetic device to adsorb the second electromagnet 3 on the outside of the smart crystal head. Under the adsorption effect, the second electromagnet 3 slid to the end away from the fixed connection between the shell 5 and the spring clip 2. The operation and maintenance personnel then pressed down the spring clip 2 to pull the smart crystal head out of the network port.

[0088] The above is only an embodiment of the present invention, and the common knowledge such as the specific structure and characteristics of the scheme is not described in detail here. It should be pointed out that for those skilled in the art, without departing from the structure of the present invention, several variations and improvements can be made, which should also be regarded as the scope of protection of the present invention, and these will not affect the effect of the implementation of the present invention and the practicality of the patent. The scope of protection required by this application shall be based on the content of its claims, and the specific implementation methods and other records in the specification can be used to interpret the content of the claims.

Claims

1. A network boundary protection perception method based on an intelligent crystal head is characterized by: The following steps are involved: S10: A locking device is provided on the RJ45 connector, and a unique identification code is provided for the locking device as a locking code. The locking device is configured to receive a first instruction from the management terminal and control the RJ45 connector to be connected to or unplugged from the network port according to the content of the first instruction. The state of the RJ45 connector being connected to or unplugged from the network port is obtained as first state information based on the locking code, and the first state information is initialized to a state of the network port being unplugged based on the locking code. S20: Obtaining first status information. When the first status information indicates a network port access status, monitoring data transmitted through the RJ45 connector as first data, obtaining information of communication terminals at both ends of the RJ45 connector that transmit the first data as first terminals, and storing the first terminal, locking code, first data, and monitoring time of the first data as a transmission log; and performing a risk assessment on the locking device corresponding to the locking code based on the data type of the first data and the first terminal in the transmission log. S30: Obtaining a transmission log, performing a data flow statistical analysis on the transmission log, and performing a risk assessment on the locking device corresponding to the locking code based on the statistical analysis results; S40: Generate a warning instruction based on the risk assessment result, and send the warning instruction to the locking device corresponding to the locking code. The locking device receives the warning instruction and controls the crystal head to connect or unplug the network port according to the warning instruction; send the transmission log corresponding to the warning instruction as a risk log to the management terminal.

2. The network boundary protection perception method based on the intelligent crystal head according to claim 1 is characterized in that: The locking device includes a body and a shell, the body is slidably connected to the shell inside the shell, and an elastic pin is provided at one end of the body; a first limiting groove is provided on one side of the shell, and when the body slides from one end of the shell to the other end, the pin of the body slides into the first limiting groove and slides from the inside of the shell to the outside of the shell; a spring is fixedly connected to the outside of the shell, one end of the spring is fixedly connected to the shell, and the spring and the shell form a certain angle, a first electromagnet is embedded in the shell on one side of the angle, a second limiting groove is provided on one side of the first electromagnet, a second electromagnet is slidably connected in the second limiting groove, and one end of the second electromagnet is fixedly connected to the body; When the first electromagnet attracts the second electromagnet, the pin slides into the first limiting groove, and the second electromagnet slides to one end of the second limiting groove, and the second electromagnet blocks the spring from pressing down under the spring; when the first electromagnet repels the second electromagnet, the pin slides into the inside of the shell, and the second electromagnet slides to the other end of the second limiting groove, and the second electromagnet no longer blocks the spring from pressing down.

3. The network boundary protection perception method based on the intelligent crystal head according to claim 2 is characterized in that: When the crystal head is connected to the network port, the location information of the crystal head is obtained as the first location according to the communication address of the network port, the location information of the management terminal is obtained as the second location, the locking code in the risk log received by the management terminal is obtained as the first code, the first position of the locking device corresponding to the first code is obtained, and a pull-out application is generated according to the distance between the first position and the second position and sent to the management terminal, and feedback information of the pull-out application is received, and the feedback information of the pull-out application is rejected or approved; when the feedback information of the pull-out application received is approved, the locking device controls the first electromagnet to repel the second electromagnet.

4. The network boundary protection perception method based on intelligent crystal head according to claim 1 is characterized in that: When performing a risk assessment on the locking device corresponding to the locking code according to the data type of the first data in the transmission log and the first terminal, the data type of the first data is first identified, the data type includes structured data, semi-structured data and unstructured data, and the first data is classified according to the identification result; then, according to the data type and the corresponding risk feature, the risk feature in the first data is identified and extracted as the first feature, and then, according to each data type of the first data, the risk assessment index is calculated according to the first feature, and the risk assessment index includes the structured data risk assessment index , semi-structured data risk assessment indicators , Unstructured Data Risk Assessment Indicators ; Then calculate the comprehensive risk value based on the risk assessment indicators of the data type , The calculation formula is as follows: (1), in, Indicates the The proportion of the data type in the first data; Based on the comprehensive risk value Risk levels are divided and stored in association with lock codes.

5. The network boundary protection perception method based on intelligent crystal head according to claim 4 is characterized in that: When performing data flow statistics analysis on transmission logs, the transmission logs are segmented into fixed time windows or dynamic windows based on flow fluctuations, and the sliding window mean is used to calculate the average value of the transmission logs. The calculation formula is shown in the following formula (2): (2), in, For the front The flow value of a time window; And based on the sliding window mean To detect sudden increase in traffic, the sudden increase rate of traffic is calculated as shown in the following formula (3): (3), If the burst rate exceeds the preset burst threshold, the corresponding data in the transmission log will be marked as a risk log; Count the total amount of data transmitted in the first data transmission in each time window, calculate the average traffic per unit time, count the traffic proportion of different protocols, detect the deviation between the traffic peak and the mean, analyze the connection frequency and session duration from the sending source to the receiving destination terminal; and calculate the entropy value of the protocol distribution in the transmission log to evaluate the traffic concentration. , The calculation formula is shown in the following formula (4): (4), in, For the Traffic proportion of each protocol; Counting the number of connections of the same first terminal in the transmission log according to the preset working time, and calculating the connection frequency based on the number of connections; Calculate the comprehensive risk value based on connection frequency, sudden increase rate and traffic concentration. (5), in, is the preset weight value.

6. The network boundary protection perception method based on intelligent crystal head according to claim 5 is characterized in that: When generating a warning instruction based on the risk assessment result, if the comprehensive risk value reaches a preset high risk level, a first type instruction is generated, and the locking device controls the crystal head to automatically unplug the network port according to the first type instruction and prohibits re-connection until the crystal head automatically connects to the network port after receiving the unlock instruction sent by the management terminal; If the comprehensive risk value reaches the preset medium risk level, a second-type instruction is generated. The locking device limits the data transmission rate of the crystal plug according to the second-type instruction and sends a risk confirmation request to the management terminal. If the risk confirmation request does not receive a risk confirmation message from the management terminal within a preset time, the second-type instruction is upgraded to a first-type instruction. If a risk confirmation message is received from the management terminal, the crystal plug is controlled to be unplugged from the network port or the comprehensive risk value is cleared according to the content of the risk confirmation message. If the comprehensive risk value is a preset low risk level, a third type of instruction is generated, the locking device maintains the crystal head access state, opens a temporary monitoring window according to the preset monitoring time to monitor the first data, and if the comprehensive risk value of the first data does not increase within the temporary monitoring time, a low risk mark is marked in the transmission log; if the comprehensive risk value of the first data increases, the third type of instruction is upgraded to a second type of instruction.

7. The network boundary protection perception method based on intelligent crystal head according to claim 6 is characterized in that: When the locking device controls the removal or connection of the crystal head to the network port according to the warning instruction, if the first type of instruction is received, the first electromagnet is energized to generate a repulsive force, driving the second electromagnet to slide toward the far end of the second limit groove, and the body slides to the end away from the shell and the spring clip, so that the crystal head is removed from the network port; when the unlocking instruction is received, the first electromagnet is energized to generate an adsorption force, driving the body to slide back to the end close to the shell and the spring clip, completing the network port access.

8. The network boundary protection perception method based on intelligent crystal head according to claim 7, characterized in that: The housing is further embedded with a temperature detection device for obtaining the temperature of the crystal head body, and the temperature data obtained by the temperature detection device is used as the actual temperature data; when storing the transmission log, the transmission log is associated with the actual temperature data obtained at the same time and stored, the data transmission time in the transmission log is statistically analyzed, and the current temperature of the crystal head is estimated as the predicted temperature data based on the statistical analysis result of the data transmission time, and the predicted temperature data is compared with the actual temperature data. When the actual difference obtained by comparison exceeds a preset difference threshold, the first electromagnet is controlled to repel the second electromagnet, and the actual temperature data is obtained again. When the actual temperature data drops to a preset non-working temperature, the first electromagnet is controlled to attract the second electromagnet, and the transmission log and the actual temperature data are obtained again, and the predicted temperature data of the crystal head is obtained based on the data transmission time in the transmission log, and the predicted temperature data is compared with the actual temperature data; If the number of times the first electromagnet repels the second electromagnet exceeds the preset number of inspections within the preset inspection time, the first electromagnet is controlled to repels the second electromagnet, and abnormal connection information is generated according to the locking code and sent to the management terminal.

9. The network boundary protection perception system based on intelligent crystal head is characterized by: The network boundary protection perception method based on the intelligent crystal head described in any one of claims 1 to 8 is used.

Citation Information

Patent Citations

  • Terminal single-path intelligent internet access lock and system and control method thereof

    CN112714107A

  • Method for testing network cable plugging-unplugging stability

    CN107707420A

  • Network port locking device

    CN119726247A